Delete a forwarded opening the way ufw accepts it, and read a fresh machine's resolver as not in use — both measured on a lab machine (hq ADR 0100)
This commit is contained in:
@@ -38,6 +38,17 @@ const (
|
||||
Unsupported Kind = "unsupported"
|
||||
)
|
||||
|
||||
// deletion is the arguments that delete a rule as `ufw show added` printed it. A route rule is
|
||||
// deleted with `route delete …`: ufw refuses `delete route …` as invalid syntax. And ufw answers
|
||||
// success when asked to delete a rule it does not hold, so every deletion is read back.
|
||||
func deletion(rule string) []string {
|
||||
w := words(rule)
|
||||
if len(w) > 0 && w[0] == "route" {
|
||||
return append([]string{"route", "delete"}, w[1:]...)
|
||||
}
|
||||
return append([]string{"delete"}, w...)
|
||||
}
|
||||
|
||||
// MeshInterface is the private network's interface, the way an opening from the mesh is known.
|
||||
// It must be the controller's overlay interface name.
|
||||
const MeshInterface = "mesh0"
|
||||
@@ -335,7 +346,7 @@ func Converge(ctx context.Context, run Runner, o *declaration.Opening) (string,
|
||||
return "unchanged", nil
|
||||
}
|
||||
for _, rule := range stale {
|
||||
if _, err := run(ctx, "ufw", append([]string{"delete"}, words(rule)...)...); err != nil {
|
||||
if _, err := run(ctx, "ufw", deletion(rule)...); err != nil {
|
||||
return "", fmt.Errorf("deleting the mesh's stale ufw rule %q: %w", rule, err)
|
||||
}
|
||||
}
|
||||
@@ -381,7 +392,7 @@ func Remove(ctx context.Context, run Runner, id string) (int, error) {
|
||||
if !markedFor(comment(rule), id) {
|
||||
continue
|
||||
}
|
||||
if _, err := run(ctx, "ufw", append([]string{"delete"}, words(rule)...)...); err != nil {
|
||||
if _, err := run(ctx, "ufw", deletion(rule)...); err != nil {
|
||||
return removed, fmt.Errorf("deleting the mesh's ufw rule %q: %w", rule, err)
|
||||
}
|
||||
removed++
|
||||
|
||||
@@ -180,9 +180,17 @@ func (f *fakeUFW) run(_ context.Context, name string, args ...string) (string, e
|
||||
case args[0] == "disable":
|
||||
f.active = false
|
||||
return "Firewall stopped and disabled on system startup\n", nil
|
||||
case args[0] == "delete":
|
||||
case args[0] == "delete" && len(args) > 1 && args[1] == "route":
|
||||
// As the real ufw answers it (captured in testdata/ufw-delete.txt): a route rule is
|
||||
// deleted with `route delete`, never `delete route`.
|
||||
return "", errors.New("ERROR: Invalid syntax")
|
||||
case args[0] == "delete", args[0] == "route" && len(args) > 1 && args[1] == "delete":
|
||||
rest := args[1:]
|
||||
if args[0] == "route" {
|
||||
rest = append([]string{"route"}, args[2:]...)
|
||||
}
|
||||
for i, r := range f.rules {
|
||||
if strings.Join(words(r), "\x00") == strings.Join(args[1:], "\x00") {
|
||||
if strings.Join(words(r), "\x00") == strings.Join(rest, "\x00") {
|
||||
f.rules = append(f.rules[:i], f.rules[i+1:]...)
|
||||
return "Rule deleted\n", nil
|
||||
}
|
||||
@@ -333,3 +341,86 @@ func TestDetectingTheFoundFirewall(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// The fixtures below were captured from a real ufw 0.36.2 on a lab machine, not written by hand:
|
||||
// ufw prints a rule back in its own shorter form, so the mark in the comment is the only thing the
|
||||
// host relies on.
|
||||
|
||||
func TestTheMarksAreReadFromWhatUfwReallyPrints(t *testing.T) {
|
||||
raw, err := os.ReadFile("testdata/ufw-show-added.txt")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
run := func(ctx context.Context, name string, args ...string) (string, error) { return string(raw), nil }
|
||||
rules, err := added(context.Background(), run)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(rules) != 7 {
|
||||
t.Fatalf("read %d rules, want 7: %q", len(rules), rules)
|
||||
}
|
||||
marked := 0
|
||||
for _, r := range rules {
|
||||
if strings.HasPrefix(comment(r), "mesh-host ") {
|
||||
marked++
|
||||
}
|
||||
}
|
||||
if marked != 5 {
|
||||
t.Errorf("read %d marked rules, want 5", marked)
|
||||
}
|
||||
if !markedFor(comment(rules[5]), "adoption.opening-tcp-8443-forwarded") {
|
||||
t.Errorf("the forwarded rule from the mesh lost its mark: %q", rules[5])
|
||||
}
|
||||
}
|
||||
|
||||
func TestEveryRealRuleIsDeletedInTheFormUfwAccepts(t *testing.T) {
|
||||
raw, err := os.ReadFile("testdata/ufw-show-added.txt")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
run := func(ctx context.Context, name string, args ...string) (string, error) { return string(raw), nil }
|
||||
rules, _ := added(context.Background(), run)
|
||||
// Each of these was run on the lab machine and answered "Rule deleted" (testdata/ufw-delete.txt).
|
||||
want := map[string]string{
|
||||
"allow 5671/tcp comment 'mesh-host adoption.opening-tcp-5671-incoming 1a2b3c4d'": "delete allow 5671/tcp comment|mesh-host adoption.opening-tcp-5671-incoming 1a2b3c4d",
|
||||
"allow in on mesh0 to any port 5432 proto tcp comment 'mesh-host adoption.opening-tcp-5432-incoming deadbeef'": "delete allow in on mesh0 to any port 5432 proto tcp comment|mesh-host adoption.opening-tcp-5432-incoming deadbeef",
|
||||
"route allow 80/tcp comment 'mesh-host adoption.opening-tcp-8081-forwarded 0badf00d'": "route delete allow 80/tcp comment|mesh-host adoption.opening-tcp-8081-forwarded 0badf00d",
|
||||
"route allow in on mesh0 to any port 443 proto tcp comment 'mesh-host adoption.opening-tcp-8443-forwarded cafe0001'": "route delete allow in on mesh0 to any port 443 proto tcp comment|mesh-host adoption.opening-tcp-8443-forwarded cafe0001",
|
||||
}
|
||||
seen := 0
|
||||
for _, r := range rules {
|
||||
w, ok := want[r]
|
||||
if !ok {
|
||||
continue
|
||||
}
|
||||
seen++
|
||||
d := deletion(r)
|
||||
got := strings.Join(d[:len(d)-1], " ") + "|" + d[len(d)-1]
|
||||
if got != w {
|
||||
t.Errorf("deleting %q\n got %s\n want %s", r, got, w)
|
||||
}
|
||||
}
|
||||
if seen != len(want) {
|
||||
t.Errorf("matched %d of %d captured rules", seen, len(want))
|
||||
}
|
||||
}
|
||||
|
||||
func TestARealUfwRulesetIsUfw(t *testing.T) {
|
||||
raw, err := os.ReadFile("testdata/ufw-active.nft")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
status, err := os.ReadFile("testdata/ufw-status-active.txt")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !statusActive(string(status)) {
|
||||
t.Fatal("the captured status does not read as active")
|
||||
}
|
||||
if refusing := Refusing(string(raw), true); len(refusing) > 0 {
|
||||
t.Errorf("a machine with ufw active and nothing else read as refusing in %v", refusing)
|
||||
}
|
||||
if refusing := Refusing(string(raw), false); len(refusing) == 0 {
|
||||
t.Error("ufw's drop chains, with ufw not known to be active, read as refusing nothing")
|
||||
}
|
||||
}
|
||||
|
||||
+478
@@ -0,0 +1,478 @@
|
||||
table ip nat {
|
||||
chain DOCKER {
|
||||
}
|
||||
|
||||
chain PREROUTING {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
xt match "addrtype" counter packets 2 bytes 1160 jump DOCKER
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type nat hook output priority dstnat; policy accept;
|
||||
ip daddr != 127.0.0.0/8 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
|
||||
chain POSTROUTING {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 0 bytes 0 xt target "MASQUERADE"
|
||||
}
|
||||
}
|
||||
table ip filter {
|
||||
chain DOCKER {
|
||||
iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain DOCKER-FORWARD {
|
||||
counter packets 0 bytes 0 jump DOCKER-CT
|
||||
counter packets 0 bytes 0 jump DOCKER-INTERNAL
|
||||
counter packets 0 bytes 0 jump DOCKER-BRIDGE
|
||||
iifname "docker0" counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain DOCKER-BRIDGE {
|
||||
oifname "docker0" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
|
||||
chain DOCKER-CT {
|
||||
oifname "docker0" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain DOCKER-INTERNAL {
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
counter packets 0 bytes 0 jump DOCKER-USER
|
||||
counter packets 0 bytes 0 jump DOCKER-FORWARD
|
||||
counter packets 0 bytes 0 jump ufw-before-logging-forward
|
||||
counter packets 0 bytes 0 jump ufw-before-forward
|
||||
counter packets 0 bytes 0 jump ufw-after-forward
|
||||
counter packets 0 bytes 0 jump ufw-after-logging-forward
|
||||
counter packets 0 bytes 0 jump ufw-reject-forward
|
||||
counter packets 0 bytes 0 jump ufw-track-forward
|
||||
}
|
||||
|
||||
chain DOCKER-USER {
|
||||
}
|
||||
|
||||
chain ufw-before-logging-input {
|
||||
}
|
||||
|
||||
chain ufw-before-logging-output {
|
||||
}
|
||||
|
||||
chain ufw-before-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw-before-input {
|
||||
iifname "lo" counter packets 0 bytes 0 accept
|
||||
xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
xt match "conntrack" counter packets 0 bytes 0 jump ufw-logging-deny
|
||||
xt match "conntrack" counter packets 0 bytes 0 drop
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
udp sport 67 udp dport 68 counter packets 0 bytes 0 accept
|
||||
counter packets 0 bytes 0 jump ufw-not-local
|
||||
ip daddr 224.0.0.251 udp dport 5353 counter packets 0 bytes 0 accept
|
||||
ip daddr 239.255.255.250 udp dport 1900 counter packets 0 bytes 0 accept
|
||||
counter packets 0 bytes 0 jump ufw-user-input
|
||||
}
|
||||
|
||||
chain ufw-before-output {
|
||||
oifname "lo" counter packets 0 bytes 0 accept
|
||||
xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
counter packets 0 bytes 0 jump ufw-user-output
|
||||
}
|
||||
|
||||
chain ufw-before-forward {
|
||||
xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
ip protocol icmp xt match "icmp" counter packets 0 bytes 0 accept
|
||||
counter packets 0 bytes 0 jump ufw-user-forward
|
||||
}
|
||||
|
||||
chain ufw-after-input {
|
||||
udp dport 137 counter packets 0 bytes 0 jump ufw-skip-to-policy-input
|
||||
udp dport 138 counter packets 0 bytes 0 jump ufw-skip-to-policy-input
|
||||
tcp dport 139 counter packets 0 bytes 0 jump ufw-skip-to-policy-input
|
||||
tcp dport 445 counter packets 0 bytes 0 jump ufw-skip-to-policy-input
|
||||
udp dport 67 counter packets 0 bytes 0 jump ufw-skip-to-policy-input
|
||||
udp dport 68 counter packets 0 bytes 0 jump ufw-skip-to-policy-input
|
||||
xt match "addrtype" counter packets 0 bytes 0 jump ufw-skip-to-policy-input
|
||||
}
|
||||
|
||||
chain ufw-after-output {
|
||||
}
|
||||
|
||||
chain ufw-after-forward {
|
||||
}
|
||||
|
||||
chain ufw-after-logging-input {
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw-after-logging-output {
|
||||
}
|
||||
|
||||
chain ufw-after-logging-forward {
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw-reject-input {
|
||||
}
|
||||
|
||||
chain ufw-reject-output {
|
||||
}
|
||||
|
||||
chain ufw-reject-forward {
|
||||
}
|
||||
|
||||
chain ufw-track-input {
|
||||
}
|
||||
|
||||
chain ufw-track-output {
|
||||
ip protocol tcp xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
ip protocol udp xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw-track-forward {
|
||||
}
|
||||
|
||||
chain INPUT {
|
||||
type filter hook input priority filter; policy drop;
|
||||
counter packets 1 bytes 76 jump ufw-before-logging-input
|
||||
counter packets 1 bytes 76 jump ufw-before-input
|
||||
counter packets 0 bytes 0 jump ufw-after-input
|
||||
counter packets 0 bytes 0 jump ufw-after-logging-input
|
||||
counter packets 0 bytes 0 jump ufw-reject-input
|
||||
counter packets 0 bytes 0 jump ufw-track-input
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type filter hook output priority filter; policy accept;
|
||||
counter packets 1 bytes 76 jump ufw-before-logging-output
|
||||
counter packets 1 bytes 76 jump ufw-before-output
|
||||
counter packets 1 bytes 76 jump ufw-after-output
|
||||
counter packets 1 bytes 76 jump ufw-after-logging-output
|
||||
counter packets 1 bytes 76 jump ufw-reject-output
|
||||
counter packets 1 bytes 76 jump ufw-track-output
|
||||
}
|
||||
|
||||
chain ufw-logging-deny {
|
||||
xt match "conntrack" limit rate 3/minute burst 10 packets counter packets 0 bytes 0 return
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw-logging-allow {
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw-skip-to-policy-input {
|
||||
counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain ufw-skip-to-policy-output {
|
||||
counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw-skip-to-policy-forward {
|
||||
counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain ufw-not-local {
|
||||
xt match "addrtype" counter packets 0 bytes 0 return
|
||||
xt match "addrtype" counter packets 0 bytes 0 return
|
||||
xt match "addrtype" counter packets 0 bytes 0 return
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 jump ufw-logging-deny
|
||||
counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain ufw-user-input {
|
||||
tcp dport 22 counter packets 0 bytes 0 accept
|
||||
tcp dport 8080 counter packets 0 bytes 0 accept
|
||||
udp dport 51820 counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw-user-output {
|
||||
}
|
||||
|
||||
chain ufw-user-forward {
|
||||
tcp dport 80 counter packets 0 bytes 0 accept
|
||||
iifname "mesh0" tcp dport 443 counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw-user-logging-input {
|
||||
}
|
||||
|
||||
chain ufw-user-logging-output {
|
||||
}
|
||||
|
||||
chain ufw-user-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw-user-limit {
|
||||
limit rate 3/minute burst 5 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
counter packets 0 bytes 0 xt target "REJECT"
|
||||
}
|
||||
|
||||
chain ufw-user-limit-accept {
|
||||
counter packets 0 bytes 0 accept
|
||||
}
|
||||
}
|
||||
table ip6 nat {
|
||||
chain DOCKER {
|
||||
}
|
||||
|
||||
chain PREROUTING {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
xt match "addrtype" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type nat hook output priority dstnat; policy accept;
|
||||
ip6 daddr != ::1 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
}
|
||||
table ip6 filter {
|
||||
chain DOCKER {
|
||||
}
|
||||
|
||||
chain DOCKER-FORWARD {
|
||||
counter packets 0 bytes 0 jump DOCKER-CT
|
||||
counter packets 0 bytes 0 jump DOCKER-INTERNAL
|
||||
counter packets 0 bytes 0 jump DOCKER-BRIDGE
|
||||
}
|
||||
|
||||
chain DOCKER-BRIDGE {
|
||||
}
|
||||
|
||||
chain DOCKER-CT {
|
||||
}
|
||||
|
||||
chain DOCKER-INTERNAL {
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
counter packets 0 bytes 0 jump DOCKER-USER
|
||||
counter packets 0 bytes 0 jump DOCKER-FORWARD
|
||||
counter packets 0 bytes 0 jump ufw6-before-logging-forward
|
||||
counter packets 0 bytes 0 jump ufw6-before-forward
|
||||
counter packets 0 bytes 0 jump ufw6-after-forward
|
||||
counter packets 0 bytes 0 jump ufw6-after-logging-forward
|
||||
counter packets 0 bytes 0 jump ufw6-reject-forward
|
||||
counter packets 0 bytes 0 jump ufw6-track-forward
|
||||
}
|
||||
|
||||
chain DOCKER-USER {
|
||||
}
|
||||
|
||||
chain ufw6-before-logging-input {
|
||||
}
|
||||
|
||||
chain ufw6-before-logging-output {
|
||||
}
|
||||
|
||||
chain ufw6-before-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw6-before-input {
|
||||
iifname "lo" counter packets 0 bytes 0 accept
|
||||
xt match "rt" counter packets 0 bytes 0 drop
|
||||
xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
xt match "conntrack" counter packets 0 bytes 0 jump ufw6-logging-deny
|
||||
xt match "conntrack" counter packets 0 bytes 0 drop
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 ip6 daddr fe80::/10 udp sport 547 udp dport 546 counter packets 0 bytes 0 accept
|
||||
ip6 daddr ff02::fb udp dport 5353 counter packets 0 bytes 0 accept
|
||||
ip6 daddr ff02::f udp dport 1900 counter packets 0 bytes 0 accept
|
||||
counter packets 0 bytes 0 jump ufw6-user-input
|
||||
}
|
||||
|
||||
chain ufw6-before-output {
|
||||
oifname "lo" counter packets 0 bytes 0 accept
|
||||
xt match "rt" counter packets 0 bytes 0 drop
|
||||
xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fe80::/10 meta l4proto ipv6-icmp xt match "icmp6" xt match "hl" counter packets 0 bytes 0 accept
|
||||
counter packets 0 bytes 0 jump ufw6-user-output
|
||||
}
|
||||
|
||||
chain ufw6-before-forward {
|
||||
xt match "rt" counter packets 0 bytes 0 drop
|
||||
xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
meta l4proto ipv6-icmp xt match "icmp6" counter packets 0 bytes 0 accept
|
||||
counter packets 0 bytes 0 jump ufw6-user-forward
|
||||
}
|
||||
|
||||
chain ufw6-after-input {
|
||||
udp dport 137 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input
|
||||
udp dport 138 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input
|
||||
tcp dport 139 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input
|
||||
tcp dport 445 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input
|
||||
udp dport 546 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input
|
||||
udp dport 547 counter packets 0 bytes 0 jump ufw6-skip-to-policy-input
|
||||
}
|
||||
|
||||
chain ufw6-after-output {
|
||||
}
|
||||
|
||||
chain ufw6-after-forward {
|
||||
}
|
||||
|
||||
chain ufw6-after-logging-input {
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw6-after-logging-output {
|
||||
}
|
||||
|
||||
chain ufw6-after-logging-forward {
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw6-reject-input {
|
||||
}
|
||||
|
||||
chain ufw6-reject-output {
|
||||
}
|
||||
|
||||
chain ufw6-reject-forward {
|
||||
}
|
||||
|
||||
chain ufw6-track-input {
|
||||
}
|
||||
|
||||
chain ufw6-track-output {
|
||||
meta l4proto tcp xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
meta l4proto udp xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw6-track-forward {
|
||||
}
|
||||
|
||||
chain INPUT {
|
||||
type filter hook input priority filter; policy drop;
|
||||
counter packets 1 bytes 128 jump ufw6-before-logging-input
|
||||
counter packets 1 bytes 128 jump ufw6-before-input
|
||||
counter packets 0 bytes 0 jump ufw6-after-input
|
||||
counter packets 0 bytes 0 jump ufw6-after-logging-input
|
||||
counter packets 0 bytes 0 jump ufw6-reject-input
|
||||
counter packets 0 bytes 0 jump ufw6-track-input
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type filter hook output priority filter; policy accept;
|
||||
counter packets 4 bytes 304 jump ufw6-before-logging-output
|
||||
counter packets 4 bytes 304 jump ufw6-before-output
|
||||
counter packets 0 bytes 0 jump ufw6-after-output
|
||||
counter packets 0 bytes 0 jump ufw6-after-logging-output
|
||||
counter packets 0 bytes 0 jump ufw6-reject-output
|
||||
counter packets 0 bytes 0 jump ufw6-track-output
|
||||
}
|
||||
|
||||
chain ufw6-logging-deny {
|
||||
xt match "conntrack" limit rate 3/minute burst 10 packets counter packets 0 bytes 0 return
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw6-logging-allow {
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
}
|
||||
|
||||
chain ufw6-skip-to-policy-input {
|
||||
counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain ufw6-skip-to-policy-output {
|
||||
counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw6-skip-to-policy-forward {
|
||||
counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain ufw6-user-input {
|
||||
tcp dport 22 counter packets 0 bytes 0 accept
|
||||
tcp dport 8080 counter packets 0 bytes 0 accept
|
||||
udp dport 51820 counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw6-user-output {
|
||||
}
|
||||
|
||||
chain ufw6-user-forward {
|
||||
tcp dport 80 counter packets 0 bytes 0 accept
|
||||
iifname "mesh0" tcp dport 443 counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain ufw6-user-logging-input {
|
||||
}
|
||||
|
||||
chain ufw6-user-logging-output {
|
||||
}
|
||||
|
||||
chain ufw6-user-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw6-user-limit {
|
||||
limit rate 3/minute burst 5 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
counter packets 0 bytes 0 xt target "REJECT"
|
||||
}
|
||||
|
||||
chain ufw6-user-limit-accept {
|
||||
counter packets 0 bytes 0 accept
|
||||
}
|
||||
}
|
||||
+40
@@ -0,0 +1,40 @@
|
||||
Rule deleted
|
||||
Rule deleted (v6)
|
||||
rc=0
|
||||
Rule deleted
|
||||
Rule deleted (v6)
|
||||
rc=0
|
||||
ERROR: Invalid syntax
|
||||
rc=1
|
||||
===ADDED2
|
||||
Added user rules (see 'ufw status' for running firewall):
|
||||
ufw allow 22/tcp
|
||||
ufw allow 8080/tcp
|
||||
ufw route allow 80/tcp comment 'mesh-host adoption.opening-tcp-8081-forwarded 0badf00d'
|
||||
ufw route allow in on mesh0 to any port 443 proto tcp comment 'mesh-host adoption.opening-tcp-8443-forwarded cafe0001'
|
||||
ufw allow 51820/udp comment 'mesh-host adoption.opening-udp-51820-incoming 11112222'
|
||||
Firewall reloaded
|
||||
reload rc=0
|
||||
===AFTERRELOAD
|
||||
3
|
||||
Firewall stopped and disabled on system startup
|
||||
===DISABLED
|
||||
Status: inactive
|
||||
/etc/ufw/user.rules
|
||||
3
|
||||
Firewall is active and enabled on system startup
|
||||
Status: active
|
||||
Rule deleted
|
||||
Rule deleted (v6)
|
||||
rc=0
|
||||
Rule deleted
|
||||
Rule deleted (v6)
|
||||
rc=0
|
||||
Could not delete non-existent rule
|
||||
Could not delete non-existent rule (v6)
|
||||
wrongcomment rc=0
|
||||
Added user rules (see 'ufw status' for running firewall):
|
||||
ufw allow 22/tcp
|
||||
ufw allow 8080/tcp
|
||||
ufw allow 51820/udp comment 'mesh-host adoption.opening-udp-51820-incoming 11112222'
|
||||
Status: active
|
||||
@@ -0,0 +1,8 @@
|
||||
Added user rules (see 'ufw status' for running firewall):
|
||||
ufw allow 22/tcp
|
||||
ufw allow 8080/tcp
|
||||
ufw allow 5671/tcp comment 'mesh-host adoption.opening-tcp-5671-incoming 1a2b3c4d'
|
||||
ufw allow in on mesh0 to any port 5432 proto tcp comment 'mesh-host adoption.opening-tcp-5432-incoming deadbeef'
|
||||
ufw route allow 80/tcp comment 'mesh-host adoption.opening-tcp-8081-forwarded 0badf00d'
|
||||
ufw route allow in on mesh0 to any port 443 proto tcp comment 'mesh-host adoption.opening-tcp-8443-forwarded cafe0001'
|
||||
ufw allow 51820/udp comment 'mesh-host adoption.opening-udp-51820-incoming 11112222'
|
||||
@@ -0,0 +1,21 @@
|
||||
Status: active
|
||||
|
||||
To Action From
|
||||
-- ------ ----
|
||||
22/tcp ALLOW Anywhere
|
||||
8080/tcp ALLOW Anywhere
|
||||
5671/tcp ALLOW Anywhere # mesh-host adoption.opening-tcp-5671-incoming 1a2b3c4d
|
||||
5432/tcp on mesh0 ALLOW Anywhere # mesh-host adoption.opening-tcp-5432-incoming deadbeef
|
||||
51820/udp ALLOW Anywhere # mesh-host adoption.opening-udp-51820-incoming 11112222
|
||||
22/tcp (v6) ALLOW Anywhere (v6)
|
||||
8080/tcp (v6) ALLOW Anywhere (v6)
|
||||
5671/tcp (v6) ALLOW Anywhere (v6) # mesh-host adoption.opening-tcp-5671-incoming 1a2b3c4d
|
||||
5432/tcp (v6) on mesh0 ALLOW Anywhere (v6) # mesh-host adoption.opening-tcp-5432-incoming deadbeef
|
||||
51820/udp (v6) ALLOW Anywhere (v6) # mesh-host adoption.opening-udp-51820-incoming 11112222
|
||||
|
||||
80/tcp ALLOW FWD Anywhere # mesh-host adoption.opening-tcp-8081-forwarded 0badf00d
|
||||
443/tcp ALLOW FWD Anywhere on mesh0 # mesh-host adoption.opening-tcp-8443-forwarded cafe0001
|
||||
80/tcp (v6) ALLOW FWD Anywhere (v6) # mesh-host adoption.opening-tcp-8081-forwarded 0badf00d
|
||||
443/tcp (v6) ALLOW FWD Anywhere (v6) on mesh0 # mesh-host adoption.opening-tcp-8443-forwarded cafe0001
|
||||
|
||||
===STATUSV
|
||||
Reference in New Issue
Block a user